Pingidentity

Pingfederate

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 10.08.2026 21:54:21
  • Zuletzt bearbeitet 11.08.2026 15:17:25

Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with active sessions.

  • EPSS 0.34%
  • Veröffentlicht 27.10.2025 14:39:41
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.

  • EPSS 0.32%
  • Veröffentlicht 15.06.2025 15:25:38
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScript code in subsequent user processing.

  • EPSS 0.29%
  • Veröffentlicht 15.06.2025 15:00:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal usage conditions.

  • EPSS 0.29%
  • Veröffentlicht 15.06.2025 14:25:39
  • Zuletzt bearbeitet 15.04.2026 00:35:42

PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory utilization.

  • EPSS 0.17%
  • Veröffentlicht 09.07.2024 23:15:10
  • Zuletzt bearbeitet 21.11.2024 08:56:21

A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only.

  • EPSS 0.44%
  • Veröffentlicht 09.07.2024 23:15:10
  • Zuletzt bearbeitet 21.11.2024 08:56:09

The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.

  • EPSS 0.24%
  • Veröffentlicht 09.07.2024 23:15:10
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON request body.

  • EPSS 0.46%
  • Veröffentlicht 10.04.2024 00:15:09
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and consume server-side resources via forged HTTP POST requests.

  • EPSS 0.93%
  • Veröffentlicht 06.02.2024 18:15:58
  • Zuletzt bearbeitet 21.11.2024 08:19:41

Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.